[nova] Help overriding Nova policies (Ussuri)

Jérôme BECOT jerome.becot at deveryware.com
Mon Dec 26 13:15:15 UTC 2022


Hello,

Someone please ?

Le 15/12/2022 à 10:52, Jérôme BECOT a écrit :
> Hello,
>
> I should miss something, and I need some help. I've updated some rules 
> that I placed in the /etc/nova/policy.yaml file. I use all defaults 
> for the olso policies (ie scope is not enabled).
>
> When I generate the fulle policy with oslopolicy-policy-generator, the 
> rules are applied in the generated output. If I test the policy with 
> oslopolicy-checker under the user's token, the results matches the 
> permissions, but Nova API continue to refuse the operation
>
> Policy check for os_compute_api:os-flavor-manage:create failed with 
> credentials
>
> I'm using the openstack cli to make the request (openstack flavor create)
>
> Thanks for your help
>
> J
>
>
-- 
*Jérôme BECOT*
Ingénieur DevOps Infrastructure

Téléphone fixe: 01 82 28 37 06
Mobile : +33 757 173 193
Deveryware - 43 rue Taitbout - 75009 PARIS
https://www.deveryware.com <https://www.deveryware.com>

Deveryware_Logo
<https://www.deveryware.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.openstack.org/pipermail/openstack-discuss/attachments/20221226/a92f0ef7/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: baniere_signature_dw_2022.png
Type: image/png
Size: 471995 bytes
Desc: not available
URL: <https://lists.openstack.org/pipermail/openstack-discuss/attachments/20221226/a92f0ef7/attachment-0001.png>


More information about the openstack-discuss mailing list